Principles For Secure & Reliable Systems • Eleanor Saitta • GOTO 2023
This presentation was recorded at GOTO Aarhus 2023. #GOTOcon #GOTOaar
Eleanor Saitta - International Security Researcher & Co-founder of Open Source Tool Trike @eleanorsaitta4486
RESOURCES
@dymaxion
ABSTRACT
Whether you’re building a new system with an established team, trying to tame a legacy ecosystem, or starting from scratch, how you think about security and reliability has a big impact on how hard they are for you to achieve.
In this session I’ll give you some tools for reframing the way you think about these problems, and explore how they’re linked, too. Specifically, we’ll look at security and reliability from the perspective of design principles, both in terms of the technical design of your system architecture and security and operations tooling, and in terms of the design of the organization that’s doing the work, especially how it communicates and makes decisions.
By the end of this talk, you should understand some of the structures you need in place to achieve good and sustainable outcomes for your team. [...]
TIMECODES
00:00 Intro
00:52 What is a system?
02:30 Properties you care about
04:17 What is security?
06:36 What is resilience?
08:07 State & logic
10:02 Immutability & ephemerality
12:54 Minimal, canonical state
15:29 Unlinkability
17:43 Code is not an asset
20:35 Declare, don’t program
25:22 Design for failure
33:20 Product security
37:33 Quick tips for starting from zero
39:19 Outro
Download slides and read the full abstract here:
RECOMMENDED BOOKS
Liz Rice • Container Security •
Liz Rice • Kubernetes Security •
Aaron Parecki • OAuth 2.0 Simplified •
Aaron Parecki • OAuth 2.0 Servers •
Erdal Ozkaya • Cybersecurity: The Beginner’s Guide •
#Security #AppSec #Cybersecurity #CNCF #EleanorSaitta #Phishing #PhishingAttack #U2F #U2FToken #WAF #Compliance #Yubikey #SSO #Resilience #ResilientSecurity #Ephemerality #Immutability #OAuth #Programming #Privacy #eBPF
Looking for a unique learning experience?
Attend the next GOTO conference near you! Get your ticket at
Sign up for updates and specials at
SUBSCRIBE TO OUR CHANNEL - new videos posted almost daily.
1 view
0
0
4 years ago 01:00:48 13
Ten Principles for Good Level Design
8 years ago 00:17:36 155
3 principles for creating safer AI | Stuart Russell
5 years ago 00:02:01 54
Diving technique Analysis and Principles - Preparation for individual development
7 years ago 00:08:22 245
Kuzushi: Principles and Exercises for Static and Dynamic Offbalancing
7 years ago 00:14:21 26
7 principles for building better cities | Peter Calthorpe
5 years ago 00:37:16 23
Basic Fundamentals and Principles for Ambushing
5 years ago 00:28:47 86
Principles For Success by Ray Dalio (In 30 Minutes)
3 years ago 00:03:55 21
VIOLENT PRINCIPLES - OFFICIAL VIDEO
6 years ago 00:25:20 73
Animation Principles In Maya
9 years ago 00:04:27 51
Principles of Program Design
2 years ago 00:43:43 4
Principles for Dealing with the Changing World Order by Ray Dalio
7 years ago 02:01:51 41
2017/06/15: 12 principles for a 21st century conservatism
4 years ago 00:48:57 15
Chelsea Finn - Principles for Tackling Distribution Shift: Pessimism, Adaptation, and Anticipation
4 years ago 00:55:24 288
Ballet’s Secret Code - a documentary (six key principles of Classical Ballet)
6 years ago 00:08:59 31
Neo Soul Chords for Beginners: Simple Principles for Voicing Them
9 years ago 00:03:53 56
BJJ Closed Guard Principles
11 years ago 00:05:21 16
Principles of economics, translated
2 years ago 00:05:32 87
3 key principles for great conversation | Emily Chamlee-Wright
6 years ago 00:02:56 9
Basic principles for making paper flower garland
3 years ago 00:52:15 22
Keynote - Some Healthy Principles About Ethics & Bias In AI | Rachel Thomas @ PyBay2018
3 years ago 00:32:35 2
Principles for Successful Entrepreneurs - Brian Tracy
5 years ago 00:03:04 4
Six principles for working with emotions
10 years ago 00:20:01 4
Practical Principles for Scalable Statistical Analysis
5 years ago 00:08:49 310
Kuzushi: Principles and Exercises for Static and Dynamic Offbalancing (Updated)